By Interestana AI Editorial — AI-drafted, human-overseen. How we report
SlowMist Links Bitget Hack to Aug. 31 Zero-Day Exploit

Blockchain security firm SlowMist has traced the recent Bitget exchange hack to a zero-day exploit that was discovered on August 31, weeks prior to the actual theft. The firm's analysis revealed that the attackers utilized a combination of two security products and a custom withdrawal tool to execute the exploit. This detailed tracing provides critical insights into the methods employed by the perpetrators, allowing for enhanced security measures and potential recovery efforts.
The investigation by SlowMist, a prominent cybersecurity company specializing in blockchain, identified specific indicators of compromise. These indicators point to a sophisticated operation that leveraged an unknown vulnerability in the platform's systems. The exploitation of a zero-day vulnerability means the flaw was unknown to the software vendor and the public, making it particularly difficult to defend against. The attackers were able to gain unauthorized access and subsequently move assets from the exchange.
SlowMist's report, released on September 1, 2023, detailed the sequence of events and the tools involved. The firm highlighted the use of a custom withdrawal tool, suggesting a tailored approach by the attackers to facilitate the illicit transfer of funds. The involvement of two security products, though not explicitly named in the initial report, implies a layered approach to the attack or the use of compromised security infrastructure. This level of detail is crucial for other exchanges and security firms to understand and fortify their own defenses against similar threats.
The Bitget hack, which occurred in early September 2023, resulted in significant financial losses, though the exact amount has not been fully disclosed by the exchange. The incident underscores the persistent and evolving threats within the cryptocurrency ecosystem. Security firms like SlowMist play a vital role in dissecting these attacks, providing forensic analysis, and sharing intelligence to bolster the overall security posture of the industry. Their findings are instrumental in helping exchanges understand their vulnerabilities and implement necessary patches and protocols to prevent future incidents. The identification of the August 31 zero-day exploit as the root cause provides a concrete starting point for remediation and further investigation into the actors behind the attack.
Original source — read the full reporting at the publisher:
Read on CoinTelegraphGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.